Earned a little money doing online tasks? A Paidwork leak exposed 23 million accounts - including bank details
Paidwork pays people small amounts for completing online tasks and surveys. If you've ever used it, a chunk of your personal details is now loose on the internet. The company was breached back in March 2026, the stolen database was quietly offered for sale on a cybercrime forum in April, and last week the whole thing - roughly 11GB - was dumped publicly. On July 19, Have I Been Pwned added it: 23,272,765 accounts.
What makes this one worse than the usual email-and-password leak is how much is in it. Alongside names, email addresses, phone numbers, home addresses, dates of birth and passwords (hashed with bcrypt, which is at least the sane way to store them), the dump reportedly includes bank account numbers and transaction records tied to how the platform pays people out. That's the kind of detail that makes a scam call or a fake "payout problem" email sound frighteningly legitimate. As of last week Paidwork still hadn't publicly acknowledged the breach.
If you have an account, change the password now, and change it anywhere else you used the same one. Keep an eye on the bank account linked to your payouts and treat any out-of-the-blue message about your Paidwork balance or a "verification" step as suspect - don't click the link, go to the site directly. You can check whether your address is in the leak at haveibeenpwned.com.
The thread running through breach after breach is reused passwords: one leak becomes a skeleton key for your other accounts. Tendvane's Privacy & accounts check runs that same breach lookup across the logins on your PC, so you can see which ones have turned up in a known leak and need a fresh, unique password first.